Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55255
Total
4360
Critical
16420
High
16093
Medium
CVE ID Severity Score Description Published
CVE-2026-12470 HIGH 7.2 The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege … Sep 22, 2026
CVE-2026-19658 CRITICAL 9.8 The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input … Sep 22, 2026
CVE-2026-13355 CRITICAL 9.8 The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to … Sep 22, 2026
CVE-2026-94493 CRITICAL 10.0 A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation … Sep 22, 2026
CVE-2026-94492 MEDIUM 6.3 A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenAPI. The manipulation … Sep 22, 2026
CVE-2026-94491 HIGH 7.3 A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. Executing a manipulation of the argument address … Sep 22, 2026
CVE-2026-93712 HIGH 7.5 Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins … Sep 22, 2026
CVE-2026-93711 MEDIUM 6.5 Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from … Sep 22, 2026
CVE-2026-93710 HIGH 7.5 Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks. … Sep 22, 2026
CVE-2026-93709 UNKNOWN — Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage … Sep 22, 2026
CVE-2026-76974 MEDIUM 5.3 SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, … Sep 22, 2026
CVE-2026-94490 MEDIUM 4.7 A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of the file src/octoprint/server/api/system.py of the component Command … Sep 22, 2026
CVE-2026-94489 MEDIUM 4.3 A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file src/octoprint/server/api/files.py of the component File Download API. … Sep 22, 2026
CVE-2026-94426 LOW 3.5 A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the … Sep 21, 2026
CVE-2026-94425 HIGH 8.8 A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the … Sep 21, 2026
CVE-2026-94627 HIGH 7.5 vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode … Sep 21, 2026
CVE-2026-94626 HIGH 7.5 vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary … Sep 21, 2026
CVE-2026-94625 MEDIUM 5.3 vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send … Sep 21, 2026
CVE-2026-94624 HIGH 7.5 vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers … Sep 21, 2026
CVE-2026-94623 HIGH 7.5 vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt … Sep 21, 2026
CVE-2026-94622 HIGH 7.5 vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with … Sep 21, 2026
CVE-2026-94540 HIGH 7.7 DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity … Sep 21, 2026
CVE-2026-94536 MEDIUM 4.3 lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions. Attackers can … Sep 21, 2026
CVE-2026-94535 HIGH 7.1 lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the … Sep 21, 2026
CVE-2026-94534 HIGH 7.1 lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can … Sep 21, 2026